{"id":"CLSA-2024-1709563150","summary":"Fix CVE(s): CVE-2023-6004, CVE-2023-6918","details":"   * SECURITY UPDATE: ProxyCommand/ProxyJump features allow injection of\n     malicious code through hostname\n     - debian/patches/CVE-2023-6004-pre1.patch: move common parser functions\n       to config_parser.c\n     - debian/patches/CVE-2023-6004-pre2.patch: prevent possible segmentation\n       fault\n     - debian/patches/CVE-2023-6004-02.patch: allow multiple '@' in usernames\n     - debian/patches/CVE-2023-6004-03.patch: simplify the hostname parsing\n       in ssh_options_set\n     - debian/patches/CVE-2023-6004-04.patch: add function to check allowed\n       characters of a hostname\n     - debian/patches/CVE-2023-6004-05.patch: add test for\n       ssh_check_hostname_syntax\n     - debian/patches/CVE-2023-6004-06.patch: check for valid syntax\n       of a hostname if it is a domain name\n     - debian/patches/CVE-2023-6004-07.patch: add test for proxycommand\n       injection\n     - debian/patches/CVE-2023-6004-08.patch: add test for ssh_is_ipaddr\n     - debian/patches/CVE-2023-6004-09.patch: add ipv6 link-local check\n       for an ip address\n     - debian/patches/CVE-2023-6004-10.patch: add tests for ipv6 link-local\n     - debian/patches/CVE-2023-6004-regression1.patch: fix regression in IPv6\n       addresses in hostname parsing\n     - debian/patches/CVE-2023-6004-regression2.patch: increase test coverage\n       for IPv6 address parsing as hostnames\n     - CVE-2023-6004\n   * SECURITY UPDATE: Unchecked return values for digests may cause DoS\n     - debian/patches/CVE-2023-6918-1.patch: systematically check return values\n       when calculating digests\n     - debian/patches/CVE-2023-6918-2.patch: detect context init failures\n     - debian/patches/CVE-2023-6918-3.patch: code coverage for\n       ssh_get_pubkey_hash()\n     - CVE-2023-6918","modified":"2026-06-04T09:47:06.490413507Z","published":"2024-03-04T14:39:13Z","upstream":["CVE-2023-6004","CVE-2023-6918"],"references":[{"type":"ADVISORY","url":"https://errata.cloudlinux.com/ubuntu18-els/CLSA-2024-1709563150.html"}],"affected":[{"package":{"name":"libssh-4","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssh-4?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.0~20170825.94fa1e38-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1709563150.json"}},{"package":{"name":"libssh-dev","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssh-dev?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.0~20170825.94fa1e38-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1709563150.json"}},{"package":{"name":"libssh-doc","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssh-doc?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.0~20170825.94fa1e38-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1709563150.json"}},{"package":{"name":"libssh-gcrypt-4","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssh-gcrypt-4?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.0~20170825.94fa1e38-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1709563150.json"}},{"package":{"name":"libssh-gcrypt-dev","ecosystem":"TuxCare:Ubuntu:18.04","purl":"pkg:deb/tuxcare/libssh-gcrypt-dev?distro=ubuntu-18.04"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.8.0~20170825.94fa1e38-1ubuntu0.7+tuxcare.els1"}]}],"database_specific":{"source":"https://github.com/cloudlinux/tuxcare-osv/tree/main/data/els_os/ubuntu18.04els/CLSA-2024-1709563150.json"}}],"schema_version":"1.7.5"}